Executive Summary

Summary
Title Sun Alert 239186 A Security Vulnerability in Solaris 10 involving the sendfilev() system call could result in Denial of Service (DoS) due to System Panic
Informations
Name SUN-239186 First vendor Publication 2008-08-11
Vendor Sun Last vendor Modification 2008-08-27
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.1 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Solaris 10 Operating System OpenSolaris

A security vulnerability in Solaris 10 related to the sendfilev() system call may allow a user who has the ability to create pages that are hosted on a Solaris 10 system using Apache 2.2.x to create a carefully crafted web page which could cause a system panic resulting in a Denial of Service (DoS) condition.
??
In addition, it may be possible for a local unprivileged user to be able to panic the system with a specially crafted program which calls the sendfile() system call (using either the sendfilev(3EXT) library routine or else directly).

State: Resolved
First released: 06-Aug-2008

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_239186_a_security

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:5128
 
Oval ID: oval:org.mitre.oval:def:5128
Title: A Security Vulnerability in Solaris 10 involving the sendfilev() system call could result in Denial of Service (DoS) due to System Panic
Description: Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.
Family: unix Class: vulnerability
Reference(s): CVE-2008-3666
Version: 1
Platform(s): Sun Solaris 10
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 304
Os 2
Os 1

Open Source Vulnerability Database (OSVDB)

Id Description
47375 Solaris sendfilev() System Call System Panic Remote DoS

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2013-02-06 19:08:16
  • Multiple Updates